Social EngineeringPhishingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICLowContained
Horizon Media
bd_28d7120ce69782f9 · schema v1 · pii pii-v1
Full breach record for Horizon Media →Horizon Media disclosed that on January 9, 2026, an unauthorized actor gained access to a limited portion of its systems via a sophisticated social engineering event. The actor copied certain files from file shares. The investigation determined that name and other personal information may have been accessed. Horizon contained the incident, notified federal law enforcement, and is offering 24 months of credit monitoring to affected individuals.
California clockDiscovered Jan 9, 2026 → Notified May 6, 2026117d ✗ CA 30-day late17 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_21c32db152c9109cVermont State AGfiled 2026-05-06Verified
- bd_33a60a56d229fca9Maine State AGfiled 2026-05-06Verified
- bd_6bb727b2cb7f614bIndiana State AGfiled 2026-05-06Verified
- bd_9b8a4ac6ec45f9a6New Hampshire State AGfiled 2026-05-06Verified
Show 1 more filing ↓Show fewer ↑up to 5d gap
- bd_611b6f87032f6dbaMassachusetts State AGfiled 2026-05-01(5d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-622892
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 6, 2026
- Raw hash
- 2514ef1877180156a66d6a8f839e9149e3bfbc6d735ca82a64593da6f468054e
Reporting entity
- Name
- Horizon Medianorm: horizon media
Victim entity
- Name
- Horizon Medianorm: horizon media
Incident
- Discovered
- Jan 9, 2026
- Materiality determined
- —
- Notification sent
- May 6, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unknown
- MITRE ATT&CK
- T1566 PhishingT1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified federal law enforcement
- Initial access
- phishing_link
Compliance
- Time to disclose
- 17 weeks(117 days from discovery to filing)
- Compliance flags
- CA 30-day late · 117dCA AG copy ≤15d · 0d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jan 9, 2026→ Notified: May 6, 2026117d 30 calendar days CA 30-day late California Consumers notified: May 6, 2026→ AG copy submitted: May 6, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.